posts:read, posts:write, and analytics:read. A scope limits what a token may do; it never grants access to a workspace that the token owner no longer manages.
Bearer header
Send the token in theAuthorization request header using the Bearer scheme:
Workspace access
Workspace resources use the workspace ID in the path:- The token is active and not expired.
- The workspace is included in the token’s allowlist.
- The token owner is still an active owner or manager of the workspace.
403 Forbidden. Passing a resource ID from another workspace does not bypass this check.
Scopes
Missing required permissions return
403 Forbidden with the required scope names.
Token lifecycle
The raw token is shown once when it is created. PostlyBee stores only its SHA-256 hash. From Settings you can review its prefix, scopes, workspace access, expiration, and last-used time, or revoke it immediately.Public API tokens and OAuth-issued MCP access tokens both use the Bearer
header, but they are different credentials and cannot be interchanged.